首页> 外文会议>Internet Measurement Conference >Forced Perspectives: Evaluating an SSL Trust Enhancement at Scale
【24h】

Forced Perspectives: Evaluating an SSL Trust Enhancement at Scale

机译:强制透视:评估SSL信任增强规模

获取原文

摘要

The certificate authority (CA) PKI system has been used for decades as a means of providing domain identity verification services throughout the Internet, but a growing body of evidence suggests that our trust in this system is misplaced. A recently proposed CA alternative, Convergence, extends the Network Perspectives system of multi-path probing to perform certificate verification. Unfortunately, adoption of Convergence and other SSL/TLS trust enhancements has been slow, in part because it is unknown how these systems perform against large workloads and realistic conditions. In this work we ask the question "What if all certificates were validated with Convergence?" We perform a case study of deploying Convergence under realistic workloads with a university-wide trace of real-world HTTPS activity. By synthesizing Convergence requests, we effectively force perspectives-based verification on an entire university in simulation. We demonstrate that through local and server caching, a single Convergence deployment can meet the requirements of millions of SSL flows while imposing under 0.1% network overhead and requiring as little as 108 ms to validate a certificate, making Convergence a worthwhile candidate for further deployment and adoption.
机译:证书颁发机构(CA)PKI系统已被使用数十年作为在整个互联网上提供域身份验证服务的手段,但越来越多的证据表明我们对该系统的信任被放错了。最近提出的CA替代,收敛,扩展了多路径探测的网络透视系统来执行证书验证。不幸的是,采用收敛和其他SSL / TLS信任增强功能速度较慢,部分原因是未知这些系统如何针对大型工作负载和现实条件执行。在这项工作中,我们提出了问题“如果所有证书都以收敛验证怎么办?”我们在具有大学的现实世界HTTPS活动的大学轨迹下,执行案例研究。通过综合收敛要求,我们有效地强迫基于透视的验证整个大学模拟。我们证明,通过本地和服务器缓存,单个收敛部署可以满足数百万SSL流量的要求,同时强加在0.1%的网络开销下,要求验证证书的108毫秒,以便进一步部署的有价值的候选人采用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号